This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Hi Teams & Friends, Hope you're good and safe ! We have configured GP VPN we have license for configuring HIP objects it was working as expected one of our new requirement was to know ANTI-MALWARE which is installed in client machines also need to know how many users installed crowd strike how many not installed and need to trigger notification to install crowd-strike. We tried KB & docs below : HIP OBJECT WORKING MECHANISM https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLSYCA4 Tried HIP Notifications https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/globalprotect/network-globalprotect-gateways/globalprotect-gateways-agent-tab/hip-notification-tab HIP OBJECT MALWARE PROTECTION TAB https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/globalprotect/objects-globalprotect-hip-objects/hip-objects-anti-malware-tab ++ We tried above but no luck kindly let me know incase any way to find out that which all the devices crowd strikes installed and not. ++ It's been great if we got solution guys....looking for your quick replies friends.....;)....;) Regards Thanks & Regards, Kirubakaran M - Security Support Engineer
... View more
Hi Team, As per below I could understand the CBC mode cipher encryption was handling by server not firewall right ? correct me If I'm wrong ...... Also for that we need to reach the concern server OS vendor or support to change encryption CBC to CTR, GCM encryption. IBM SERVER https://www.ibm.com/support/pages/disabling-cipher-block-chaining-cbc-mode-ciphers-and-weak-mac-algorithms-ssh-ibm-puredata-system-operational-analytics PA-Community-post https://live.paloaltonetworks.com/t5/general-topics/ssh-ssl-issues-reported-from-vulnerability-assessment/td-p/143014 Regards Kirubakaran.M
... View more
Dear Friends, Hope you are all doing good!!! I am facing issue SSL VPN for particular ubuntu 14.0 user. Here is my findings and observation below: ================================ ++ Customer having 4 diff ISP provider ++ The user was in full tunnel mode in GP VPN. ++ Out of 4 ISP only one ISP ubuntu14 machine getting connected with GP VPN and able to access local network under Palo firewall. ++ same 4 ISP was working as expected on windows PC(we booted dual boot on same laptop). ++ But, MY QUERY was why the same 4 ISP can't connect the GP VPN on linux machine ? while it was happening on windows why it was not happening in linux(machine) GP client? ++ Is there any separate working mechanism for windows and linux machine? How to Resolve and find RCA for this issue ? Regards Kirubakaran
... View more